Cisco SGE2000 Reference Guide - Page 62

Defining Profile Rules, Source IP Address, Network Mask, Prefix Length, Action, Apply, Security Suite - lag

Page 62 highlights

Chapter 4 SGE2000/SGE2000P Gigabit Ethernet Switch Reference Guide - Port - Specifies the port on which the access profile is defined. - LAG - Specifies the LAG on which the access profile is defined. - VLAN - Specifies the VLAN on which the access profile is defined. • Source IP Address - Defines the interface source IP address to which the access profile applies. The Source IP Address field is valid for a subnetwork. • Network Mask - Determines what subnet the source IP Address belongs to in the network. • Prefix Length - Defines the number of bits that comprise the source IP address prefix, or the network mask of the source IP address. • Action - Defines the action attached to the rule. The possible field values are: - Permit - Permits access to the device. - Deny - Denies access to the device. This is the default. 3. Define the relevant fields. 4. Click Apply. The access profile is added, and the device is updated. Defining Profile Rules Access profiles can contain up to 128 rules that determine which users can manage the switch module, and by which methods. Users can also be blocked from accessing the device. Rules are composed of filters including: • Rule Priority • Interface • Management Method • IP Address • Prefix Length • Forwarding Action To define profile rules: 1. Click Security Suite > Access Method > Profile Rules. The Profile Rules Page opens: 54 Chapter 4: Configuring Device Security Defining Access Method

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286

54
Chapter 4: Configuring Device Security
Defining Access Method
SGE2000/SGE2000P Gigabit Ethernet Switch Reference Guide
Chapter
4
Port
— Specifies the port on which the access profile is defined.
LAG
— Specifies the LAG on which the access profile is defined.
VLAN
— Specifies the VLAN on which the access profile is defined.
Source IP Address
— Defines the interface source IP address to which the access profile applies.
The Source IP Address field is valid for a subnetwork.
Network Mask
— Determines what subnet the source IP Address belongs to in the network.
Prefix Length
— Defines the number of bits that comprise the source IP address prefix, or the
network mask of the source IP address.
Action
— Defines the action attached to the rule. The possible field values are:
Permit
— Permits access to the device.
Deny
— Denies access to the device. This is the default.
3.
Define the relevant fields.
4.
Click
Apply
. The access profile is added, and the device is updated.
Defining Profile Rules
Access profiles can contain up to 128 rules that determine which users can manage the switch module,
and by which methods. Users can also be blocked from accessing the device. Rules are composed of
filters including:
Rule Priority
Interface
Management Method
IP Address
Prefix Length
Forwarding Action
To define profile rules:
1.
Click
Security Suite
>
Access Method
>
Profile Rules
. The
Profile Rules Page
opens: